Flaw in COLDCARD wallet's random number generator linked to $88.6 million Bitcoin theft

Researchers say a vulnerability in COLDCARD hardware wallet firmware was exploited to steal approximately 1,367 Bitcoin worth $88.6 million from 4,585 wallets, with the thefts occurring across three waves beginning July 30, according to Galaxy Research and Chainalysis.
Block's Bitcoin Engineering and Security teams traced the issue to an integration error in COLDCARD's random number generation code that caused the device to use a deterministic software generator instead of its hardware RNG. The fallback generator relied on the device's microcontroller identifier and system timing values, allowing attackers to generate possible wallet seeds offline, match them against blockchain addresses, and steal funds from affected wallets.
Coinkite disclosed the flaw on July 31, two days after researchers identified it. Affected devices include Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Updated firmware is available, Lawrence Abrams reports for BleepingComputer.